help: include unsafe SHA-1 build info in version

In 06c92dafb8 (Makefile: allow specifying a SHA-1 for non-cryptographic uses, 2024-09-26), support for unsafe SHA-1 is added. Add the unsafe SHA-1 build info to `git version --build-info` and update corresponding documentation. Signed-off-by: Justin Tobler <jltobler@gmail.com> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Justin Tobler committed Apr 3, 2025 at 09:05 UTC 6cf65440d39250880e747d2c5281881e95eb9499
3 files changed +10 -1
Documentation/git-version.adoc
+3 -1
@@ -27,7 +27,9 @@ The libraries used to implement the SHA-1 and SHA-256 algorithms are displayed
27 in the form `SHA-1: <option>` and `SHA-256: <option>`. Note that the SHA-1
28 options `SHA1_APPLE`, `SHA1_OPENSSL`, and `SHA1_BLK` do not use a collision
29 detection algorithm and thus may be vulnerable to known SHA-1 collision
30 -attacks.
30 +attacks. When a faster SHA-1 implementation without collision detection is used
31 +for only non-cryptographic purposes, the algorithm is displayed in the form
32 +`non-collision-detecting-SHA-1: <option>`.
33
34 GIT
35 ---
hash.h
+3
@@ -20,12 +20,14 @@
20 #endif
21
22 #if defined(SHA1_APPLE_UNSAFE)
23 +# define SHA1_UNSAFE_BACKEND "SHA1_APPLE_UNSAFE"
24 # include <CommonCrypto/CommonDigest.h>
25 # define platform_SHA_CTX_unsafe CC_SHA1_CTX
26 # define platform_SHA1_Init_unsafe CC_SHA1_Init
27 # define platform_SHA1_Update_unsafe CC_SHA1_Update
28 # define platform_SHA1_Final_unsafe CC_SHA1_Final
29 #elif defined(SHA1_OPENSSL_UNSAFE)
30 +# define SHA1_UNSAFE_BACKEND "SHA1_OPENSSL_UNSAFE"
31 # include <openssl/sha.h>
32 # if defined(OPENSSL_API_LEVEL) && OPENSSL_API_LEVEL >= 3
33 # define SHA1_NEEDS_CLONE_HELPER_UNSAFE
@@ -42,6 +44,7 @@
44 # define platform_SHA1_Final_unsafe SHA1_Final
45 # endif
46 #elif defined(SHA1_BLK_UNSAFE)
47 +# define SHA1_UNSAFE_BACKEND "SHA1_BLK_UNSAFE"
48 # include "block-sha1/sha1.h"
49 # define platform_SHA_CTX_unsafe blk_SHA_CTX
50 # define platform_SHA1_Init_unsafe blk_SHA1_Init
help.c
+4
@@ -805,6 +805,10 @@ void get_version_info(struct strbuf *buf, int show_build_options)
805 strbuf_addf(buf, "zlib: %s\n", ZLIB_VERSION);
806 #endif
807 strbuf_addf(buf, "SHA-1: %s\n", SHA1_BACKEND);
808 +#if defined SHA1_UNSAFE_BACKEND
809 + strbuf_addf(buf, "non-collision-detecting-SHA-1: %s\n",
810 + SHA1_UNSAFE_BACKEND);
811 +#endif
812 strbuf_addf(buf, "SHA-256: %s\n", SHA256_BACKEND);
813 }
814 }